From 33233dec10a287da9bd3a60c7a3297654fb8dcae Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 23:52:53 +0000 Subject: [PATCH 1/2] build(deps): bump golang.org/x/image from 0.45.0 to 0.46.0 Bumps [golang.org/x/image](https://github.com/golang/image) from 0.45.0 to 0.46.0. - [Commits](https://github.com/golang/image/compare/v0.45.0...v0.46.0) --- updated-dependencies: - dependency-name: golang.org/x/image dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- go.mod | 6 +++--- go.sum | 12 ++++++------ 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/go.mod b/go.mod index b26c01ce..df597672 100644 --- a/go.mod +++ b/go.mod @@ -74,8 +74,7 @@ require ( github.com/gen2brain/jxl v0.2.0 github.com/goccy/go-yaml v1.19.2 github.com/nicksnyder/go-i18n/v2 v2.6.1 - golang.org/x/image v0.45.0 - golang.org/x/text v0.41.0 + golang.org/x/text v0.42.0 ) require ( @@ -107,8 +106,9 @@ require ( github.com/srwiley/rasterx v0.0.0-20220730225603-2ab79fcdd4ef // indirect github.com/stretchr/testify v1.11.1 // indirect github.com/yuin/goldmark v1.8.2 // indirect + golang.org/x/image v0.46.0 // indirect golang.org/x/net v0.57.0 // indirect - golang.org/x/sys v0.47.0 // indirect + golang.org/x/sys v0.48.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect ) diff --git a/go.sum b/go.sum index 191cc20e..a3831697 100644 --- a/go.sum +++ b/go.sum @@ -70,14 +70,14 @@ github.com/yuin/goldmark v1.8.2 h1:kEGpgqJXdgbkhcOgBxkC0X0PmoPG1ZyoZ117rDVp4zE= github.com/yuin/goldmark v1.8.2/go.mod h1:ip/1k0VRfGynBgxOz0yCqHrbZXhcjxyuS66Brc7iBKg= go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= -golang.org/x/image v0.45.0 h1:FMb1nTbH5H9vF55SriQHgFw5GnNL9Jg6L25BwXKzhB0= -golang.org/x/image v0.45.0/go.mod h1:n62x/7RqlwXDvGsSU4u6IUTUf6KghUZ9Bt7cG/T9Fx4= +golang.org/x/image v0.46.0 h1:b1+oYj0Jbp6K5MDT4i4/eZpYlk3V8SJhhDKh6LBHAyQ= +golang.org/x/image v0.46.0/go.mod h1:3B3W05VGVQyuXucLINLjXKrqISASfi4Xj+iCVkLMwew= golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= -golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs= -golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= -golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8= -golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M= +golang.org/x/sys v0.48.0 h1:bbX/i/6MgT9BVLM9RT1thmxL04yeTAhbEz4SyadbXoo= +golang.org/x/sys v0.48.0/go.mod h1:hNLxWAXmnKAxqDtdwIYC4bM9oQPEecfsnNMuSxOs3og= +golang.org/x/text v0.42.0 h1:JbOZXgfeCPU9gacVtYliJqOhD+zhrEqK4LfdpmlUZqI= +golang.org/x/text v0.42.0/go.mod h1:ojzP1Z+2QtioaF8DTtO8K5q7JWVVYwZKenzujK0Zd0E= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f h1:BLraFXnmrev5lT+xlilqcH8XK9/i0At2xKjWk4p6zsU= gopkg.in/check.v1 v1.0.0-20200227125254-8fa46927fb4f/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= From 0965273194983aaf06e1e799a1e41f4f10d02e88 Mon Sep 17 00:00:00 2001 From: DonislawDev Date: Tue, 22 Sep 2026 08:47:54 +0200 Subject: [PATCH 2/2] build: the notices name the versions this bump actually links x/image 0.46.0 changes no Go file at all - its own go.mod asks for x/text 0.42.0 and x/sys 0.48.0, which is why this pull request carries #111 whole. x/text's change is in unicode/norm, which this project uses only to compare two names and never to write one, so no generated byte moves. Every byte stability guard was green on three systems in the bot's own CI run. The only red was the notices file, which names versions by hand, and it now says 0.42.0, 0.46.0 and 0.48.0. Measured on the two copies in the module cache rather than read from release notes: x/sys adds one Windows constant, x/image/webp still holds a decoder and no encoder, so the claim in webp.go stands at 0.46.0. The comment in dependabot.yml said every bump is checked locally with the full suite before it is accepted. The owner's decision of 2026-09-22 has the full suite run in CI on the pull request instead, on three systems, and the sentence now says what is still read by hand. Co-Authored-By: Claude Opus 5 --- .github/dependabot.yml | 10 +++++++--- CHANGELOG.md | 11 +++++++++++ THIRD-PARTY-NOTICES.md | 6 +++--- internal/format/webp/webp.go | 9 +++++---- 4 files changed, 26 insertions(+), 10 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 21170067..314d7ced 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -33,9 +33,13 @@ version: 2 # every one of them, and GPL-3.0 makes that a real question rather than # a formality. # -# None of these are merged on a green tick alone. Every one is checked locally -# first, with the full suite, before it is accepted - the owner's rule, and the -# reason the two points above are written here rather than left to be +# None of these are merged on a green tick alone. Every one is read before it +# is accepted: which files of the module changed between the two versions +# (diff the two copies in the module cache, not the release notes), whether +# anything the command line binary links is among them, and what the byte +# stability guards said. The full suite runs in CI on the pull request, on +# three systems - the owner's decision of 2026-09-22, replacing the earlier +# rule that it ran locally first. Written here rather than left to be # rediscovered on a Monday morning by whoever opens the pull request. # # Grouped for actions and ungrouped for Go on purpose. An action bump is one diff --git a/CHANGELOG.md b/CHANGELOG.md index 4245d57a..1fb45d87 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -16,6 +16,17 @@ because it turns other people's test suites red. ### Changed +- **Two names are compared with a corrected Unicode normaliser.** The + library that decides whether two file names are one name spelled two ways, + `golang.org/x/text`, moves from 0.41.0 to 0.42.0, and that release fixes how + a few rare sequences compose - a combining mark after a Hangul syllable, + and a mark that an earlier letter should have kept apart. A recipe naming + such a pair is now refused as a collision, where an older build wrote two + files that macOS would have stored as one. No generated byte moves: the + normaliser only compares names and never rewrites the one written to disk. + The window's `golang.org/x/image` (0.46.0, no code change) and + `golang.org/x/sys` (0.48.0) move with it, and the third-party notices name + the new numbers. - **The window says where things begin and end.** Every field's name now stands above its box rather than beside it, in a lighter ink than the value under it, so a form reads as a column of named boxes. A section diff --git a/THIRD-PARTY-NOTICES.md b/THIRD-PARTY-NOTICES.md index 208782d2..c4833c50 100644 --- a/THIRD-PARTY-NOTICES.md +++ b/THIRD-PARTY-NOTICES.md @@ -76,7 +76,7 @@ Source: ## golang.org/x/text -Version 0.41.0. Supplies Unicode normalisation, used to decide whether two file +Version 0.42.0. Supplies Unicode normalisation, used to decide whether two file names are one name spelled two ways. ``` @@ -273,9 +273,9 @@ is the module's own MIT, carried unchanged. | `github.com/srwiley/oksvg` | v0.0.0-20221011165216-be6e8873101c | BSD-3-Clause | (c) 2018, Steven R Wiley | | `github.com/srwiley/rasterx` | v0.0.0-20220730225603-2ab79fcdd4ef | BSD-3-Clause | (c) 2018, Steven R Wiley | | `github.com/yuin/goldmark` | v1.8.2 | MIT | (c) 2019 Yusuke Inuzuka | -| `golang.org/x/image` | v0.45.0 | BSD-3-Clause | 2009 The Go Authors. | +| `golang.org/x/image` | v0.46.0 | BSD-3-Clause | 2009 The Go Authors. | | `golang.org/x/net` | v0.57.0 | BSD-3-Clause | 2009 The Go Authors. | -| `golang.org/x/sys` | v0.47.0 | BSD-3-Clause | 2009 The Go Authors. | +| `golang.org/x/sys` | v0.48.0 | BSD-3-Clause | 2009 The Go Authors. | The five licence texts follow, one copy each. They differ only in the copyright line, which is in the table above for every module. diff --git a/internal/format/webp/webp.go b/internal/format/webp/webp.go index 95d4fc5c..e6ef60c0 100644 --- a/internal/format/webp/webp.go +++ b/internal/format/webp/webp.go @@ -8,10 +8,11 @@ // // Written by hand rather than taken from a library, and the reason is // measured rather than assumed: x/image/webp holds decode.go and doc.go and -// nothing else, so the ecosystem offers no encoder to take. Checked at v0.43.0 -// and again at v0.45.0 on 2026-09-02, when the module was raised - a claim -// about what somebody else ships has to be re-read when their version moves, -// not carried across with the number changed. Pure Go +// nothing else, so the ecosystem offers no encoder to take. Checked at v0.43.0, +// again at v0.45.0 on 2026-09-02 and again at v0.46.0 on 2026-09-22, each time +// the module was raised - a claim about what somebody else ships has to be +// re-read when their version moves, not carried across with the number +// changed. Pure Go // encoders exist outside it, and taking one would have put somebody else's // release inside the byte stability contract D11 - their next version would // move the hashes in our users' test suites. See docs/STACK.md section 4.2.